PT-2017-2634 · D Link · D-Link Dir-615 Wireless N 300 Router
Published
2017-06-11
·
Updated
2023-04-26
·
CVE-2017-9542
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-615 Wireless N 300 Router
Description
The issue is related to weaknesses in the authentication procedure of the router's firmware. It can be exploited by a remote attacker using a modified POST request to the "login.cgi" endpoint, allowing them to bypass authentication. The problem arises because the router fails to properly validate the
password field. Successful exploitation enables an attacker to gain control of the affected device.Recommendations
For D-Link DIR-615 Wireless N 300 Router, consider disabling access to the "login.cgi" endpoint until a patch is available to prevent exploitation. Restricting access to this endpoint can minimize the risk of unauthorized control. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-615 Wireless N 300 Router